HackingTargetedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
CF Arcis XII, LLC
bd_e5ae6837d09be40f · schema v1 · pii pii-v1
Full breach record for CF Arcis XII, LLC →CF Arcis XII LLC dba Arcis Golf notified consumers of a data breach occurring around November 16, 2023. Unauthorized access resulted in the acquisition of personal information including names, addresses, dates of birth, driver's license numbers, bank account numbers, and Social Security numbers. The company engaged forensic specialists, notified law enforcement, and enhanced network security. Affected individuals were offered 12 months of credit monitoring and fraud assistance.
Vermont clock✗ VT AG >45 bday32 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_a33cef78767e9d2aIndiana State AGfiled 2024-06-27Verified
- bd_46028f9028080ac8California State AGfiled 2024-07-01(4d gap)Verified
- bd_b3555c09256d3ee4Montana State AGfiled 2024-07-01(4d gap)Candidate
- bd_fca153312c53e974New Hampshire State AGfiled 2024-07-01(4d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 5d gap
- bd_4fcd5897dd3b61d7Washington State AGfiled 2024-07-02(5d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2024-06-27-cf-arcis-xii-dba-arcis-golf-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 27, 2024
- Raw hash
- dcd168429a1f5db00654b80fd955070bc32797db9d0d4582c7b405b5ff404779
Reporting entity
- Name
- CF Arcis XII, LLCnorm: cf arcis xii
Victim entity
- Name
- CF Arcis XII, LLCnorm: cf arcis xii
Incident
- Discovered
- Nov 16, 2023
- Materiality determined
- May 28, 2024
- Notification sent
- Jun 27, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Reported the incident to law enforcement
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 32 weeks(224 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.